ZachXBT’s Undercover Operation Uncovers Chinese Money Laundering for Lazarus Group
On-chain investigator ZachXBT has exposed a sophisticated Chinese money laundering operation linked to North Korea’s Lazarus Group. In an undercover operation, he invested $349,700 to infiltrate a criminal network processing over $1 billion in stolen cryptocurrency. ZachXBT identified more than $12 million in digital wallets connected to the $1.5 billion Bybit breach, leading Tether to freeze 442,000 USDT tied to the network.
ZachXBT began his investigation in February 2025, posing as a client to gather intelligence. He communicated with a contact using the pseudonym Jimmy Green, who revealed details about the laundering operation’s structure. The network, based in China and Hong Kong, processed funds from multiple cryptocurrency hacks for the Lazarus Group. A key breakthrough came when ZachXBT linked a transaction involving 1.192 Bitcoin and 51.73 Ether to a THORChain swap of Bybit-related assets.
The investigation led to the freezing of $12 million in funds traced to Bybit, with Tether immobilizing 442,000 USDT. The FBI attributed the Bybit attack to North Korean entities, while Chainalysis reported that North Korean-linked hackers took $2.02 billion in cryptocurrency throughout 2025. ZachXBT delayed publishing his findings until October 2026 due to the sensitive nature of the ongoing investigation.
While ZachXBT’s findings have not been fully validated in legal proceedings, his evidence has been shared with law enforcement. The investigation continues, with Chainalysis tracking proceeds from other breaches, including the $387 million Bitget breach in September 2026.